When most people picture a cyber attack, they imagine something obvious: computers suddenly becoming inaccessible, a ransom message appearing on screen or systems grinding to a halt.
But a cyber breach isn’t always that easy to spot.
An attacker who gains access to an email account, user credentials or part of your network may benefit from remaining unnoticed. The longer suspicious activity goes undetected, the more opportunity there may be to access information, compromise additional accounts or use a trusted identity to target other people.
For small and medium-sized businesses, this raises an important question:
Would you know if your business had already been compromised?
Understanding some of the warning signs, and knowing what to do when you find them, should be an important part of your cybersecurity strategy.
1. Unusual Login Activity
An unfamiliar login can be one of the first indications that an account has been compromised.
This could include attempts to access an account from an unexpected location, an unfamiliar device or at unusual times of the day.
Of course, not every unusual login means you’ve suffered a cyber attack. Employees travel, work remotely and use different devices. However, unexplained activity should always be investigated rather than ignored.
Businesses should have appropriate security measures in place to help identify suspicious account activity and should encourage employees to report anything they don’t recognise.
Multi-factor authentication (MFA) can also provide an additional layer of protection by requiring more than a password before access is granted.
2. Unexpected Password Resets
An employee receives a password reset notification… but they didn’t request one.
It might seem like something that can simply be deleted and forgotten, but unexpected password activity can indicate that someone is attempting to gain access to an account.
Similarly, if an employee suddenly finds themselves locked out of an account or their usual password no longer works, it should be investigated.
The key is creating a culture where employees know that unexpected security notifications aren’t just an inconvenience. They’re something the business needs to know about.
3. Emails Nobody Remembers Sending
Email accounts are particularly attractive targets for cyber criminals.
Once an attacker has access to a legitimate business email account, they may be able to use the trust associated with that address to target colleagues, customers or suppliers.
For example, an employee might discover emails in their sent folder that they don’t recognise. Colleagues could receive unusual requests apparently sent from a genuine account, or customers might report receiving unexpected messages.
Changes to mailbox settings, such as unfamiliar forwarding rules, can also warrant investigation.
If something doesn’t look right, don’t assume it’s simply a technical glitch.
4. Unexplained Changes to Accounts and Permissions
Access to your business systems should be carefully controlled.
Employees should generally have access to the information and systems they need to perform their jobs, rather than being given unnecessary privileges.
Unexpected changes can therefore be a warning sign.
Perhaps a new user account appears without an obvious explanation. An existing user suddenly has additional permissions. Or security settings have been changed without anyone knowing why.
These changes don’t automatically mean you’ve been breached, but they shouldn’t be overlooked.
Regularly reviewing who has access to your systems, and what level of access they have, can help businesses identify unusual activity while also reducing unnecessary exposure.
5. Unusual System or Network Behaviour
Sometimes the first indication of a problem isn’t an account notification at all.
Unexplained system behaviour, unexpected network activity, new applications or other changes that nobody within the business can account for could warrant further investigation.
The difficulty is separating genuine warning signs from everyday IT problems.
A slow computer doesn’t automatically mean your organisation is under cyber attack. Equally, repeatedly dismissing unusual behaviour as “just an IT issue” could mean genuine suspicious activity goes unnoticed.
Having appropriate monitoring and professional IT support can help businesses identify when something requires a closer look.
You’ve Spotted Something Suspicious. What Happens Next?
Detecting unusual activity is only useful if your organisation knows what to do about it.
That’s why businesses should think about incident response before an incident occurs.
Who does an employee contact if they receive a suspicious security notification? Who is responsible for investigating it? What happens if an account needs to be secured? Who makes decisions if important systems have to be taken offline?
Trying to answer these questions for the first time in the middle of a cyber incident can waste valuable time.
A clear incident response process can help everyone understand their responsibilities and allow the organisation to respond in a more structured way.
Depending on the nature of an incident, businesses may also have legal, regulatory, contractual or insurance obligations to consider. Having appropriate professional support available can therefore be particularly valuable.
Prevention Is Only Half the Job
No organisation can realistically approach cybersecurity by assuming it will never be targeted.
Strong passwords, MFA, security updates, firewalls, employee training and other preventative measures can all play an important role in reducing cyber risk.
But prevention is only one part of a wider cybersecurity strategy.
Businesses also need to consider detection, response and recovery.
- How quickly would you notice suspicious activity?
- Would your employees know who to tell?
- Could you determine which accounts or systems had been affected?
- And how quickly could your business recover?
Thinking about those questions now can put your organisation in a much stronger position if something does happen.
Don’t Wait for an Attack to Find the Gaps
Cybersecurity isn’t simply about installing security software and hoping for the best.
It requires multiple layers of protection covering your technology, systems, data and people, alongside the ability to identify and respond to suspicious activity.
For small businesses in particular, knowing where your vulnerabilities are can make it much easier to prioritise the areas that need attention.
At Ashdown Solutions, we help businesses understand their cyber risks and put practical security measures in place to better protect their systems, data and employees.
Not sure how prepared your business would be for a cyber incident?
Speak to the Ashdown Solutions team about your cybersecurity requirements and find out where your organisation could be exposed.